A world engine controlled with Python
Omniweft
An early world engine with bounded worker lifecycle and explicit retry recovery. Late proposals cannot mutate the world; uncertain delivery can recover the original receipt without duplicating an edit.
Incubating. The room has Windows GPU evidence; native parenting and bounded queries have separate CPU records and are unsupported by the Python SDK. Linux physical GPU verification, physics and persistence remain unavailable.

Latest verified change · PR #22 / PR-015 ↗ · Merged
Worker recovery preserves the authority boundary
PR #21 adds bounded lifecycle, cancellation and explicit same-request retry. PR #22 preserves timed_out / DEADLINE_EXPIRED when restart first observes an expired ready proposal. The parent and native host must survive; process separation is not an OS sandbox.
Source checked . Documentation and retained evidence review, not a new runtime test.
Read change evidence ↗| Phase | Status | World revision |
|---|---|---|
| timeout | timed_out | 0 |
| cancelled | cancelled | 0 |
| crashed | crashed | 0 |
| superseded | superseded | 0 |
| replacement | committed | 1 |
| restarted | committed | 2 |
Recorded statuses from the public archive. Prevented proposals leave the world at revision zero.
Explore the actual output / 3D
Step inside the saved room.
Turn the room, inspect each object and compare a rejected change with an accepted move. These are the five unit-cube prefabs from the retained workshop scene.
Can a rejected edit leave the room unchanged?
Compare the rejected change with the initial room, then inspect the accepted move. The scene version tells you which edit took effect.
- Five objects from saved engine states
- Three retained states to compare
- Original native captures below
Five objects. Three retained room states.
A saved view is shown. Open 3D to inspect the evidence from another angle.
Geometry, transforms and revisions come from saved engine states. Colors and lighting distinguish the objects in this browser rendering. Original native engine captures are shown below. No new engine or AI run is implied.
In plain terms
Build a five-block room from Python, reject an out-of-bounds edit, then rearrange it within the allowed region.
Why it matters
Software tools need to know whether a requested change actually happened. Omniweft separates changes to the world from the optional graphics that display it.
Follow the example, step by step
Connect locally
A Python client starts an authenticated session with the native engine on the same computer.
Submit a change
Create or move an object. A rejected batch leaves the world unchanged.
Read back the world
Inspect the current in-memory state. If a response is uncertain, check the world before trying again.
Retry the original request within its existing authority
Documented approach
The opt-in worker supervisor retains the exact prepared transaction after uncertain delivery. Explicit retry goes through the existing authenticated policy host and can recover the original receipt without duplicating the edit.
Alternative and scope
Restarting a worker with a new request key could repeat an edit that already committed. Replacement authoring therefore remains blocked while the outcome is uncertain. Legacy profiles keep their resync_only contract.
Cost of the choice
The fixed four-receipt, 2,000 ms retention window is bounded. Expiry requires reconciliation. The parent and volatile native host must survive; separate native persistence does not extend durability to this worker path.
What the evidence establishes
The retained CPU transport fixture loses a post-commit response and recovers the receipt after provider restart without duplicate creation or a second revision increment. PR #22 additionally corrects ready-proposal expiry on restart. No new engine run is claimed here.
Read the decision source (opens in a new tab)Captured output / 18 September 2026
A room built through Python, one checked change at a time.
Five blocks stand in for a floor, two walls, a table and a stool. A scripted Python client builds the room, attempts a forbidden edit, then rearranges the furniture within its permissions.
The rejected plan leaves revision 3 intact. Only the corrected plan changes the room to revision 4.
Retained Windows GPU captures from 18 September 2026. Original 320 × 240 pixels, enlarged here. This is a scripted five-block fixture, not a language-model run or a finished game. Linux physical GPU verification remains not_run.
Recorded data / 20 September 2026
Ask the world a question. Inspect the exact answer.
Choose a saved native query to see which objects it returned. Compare a retained page with a fresh query after an edit, then inspect a combined filter and a session without read permission.
A snapshot stays stable while the world changes. New queries see the new revision.
Diagrams plot the x bounds and centers in retained Windows CPU query pages from 20 September 2026. Rows follow UUID order; they do not show every object in the world. This native API is separate from the Python SDK and remote policy gateways. No engine or GPU run was performed for this refresh.
Recorded data / 19 September 2026
Follow a child through five recorded transactions.
Choose a step in the native hierarchy example. Each diagram plots the actual saved world positions along the x axis, with the recorded parent link and transaction receipt.
A rejected cycle leaves the complete previous world intact.
Diagrams derived from retained Windows CPU snapshots, not rendered engine frames. This fixture has y = z = 0. Native hierarchy is unsupported by the current Python SDK and policy profiles; no physics or physical GPU result is implied.
Local control and downstream presentation
An architectural map of the room showcase: a scripted Python client submits scoped edits, the owner commits complete state, and optional Vulkan presentation captures the result. This diagram is editorial; the gallery holds actual output.
A worker proposes, the parent retains authority
The opt-in supervisor keeps at most eight request statuses and one active request, with at most two bounded children while draining old output. A worker receives no session token, epoch or prepared transaction. Timeout, cancellation, crash and supersession before submission prevent mutation; late output cannot revive a terminal proposal.
Submission crosses the cancellation boundary. Once it starts, cancellation returns too_late. If delivery is uncertain, the parent retains the exact prepared transaction for an explicit retry through policy.retry.v1. The existing four-receipt, 2,000 ms retention window does not extend on replay. Expired retention requires reconciliation, never a silently replaced request key.
PR #22 applies expiry before restart supersession. Restart just before the deadline can supersede a ready proposal; at or after the deadline it remains timed_out with DEADLINE_EXPIRED. Prepared and uncertain requests retain their recovery rules. Local statuses are not persistent, and this volatile policy host is not crash-durable.
Keep native history separate from worker recovery
The intervening merged slices add concurrent proposals and retained retries, bounded native undo/redo, recorded nonphysics command replay and native crash-safe persistence. Native history supports limited root tag and transform edits; it is not physical rewind or a remote editor endpoint.
Native persistence is a separate opt-in store with its own recovery contract. It does not make the worker supervisor or the volatile policy.retry.v1 host durable across a host crash. The worker article keeps that distinction explicit.
Ask only within the permission you hold
A native query combines required tags with an optional axis-aligned region. The host supplies an immutable read grant; tags never confer authority. A grant region must contain the complete cube, while the query region uses inclusive intersection.
Results arrive in UUID order, with bounded row and byte counts. A retained snapshot replays consistently after world edits. A successful new query replaces the earlier cursor, while an expired or closed session requires resynchronization.
The gallery plots real returned bounds from the Windows CPU proof. This does not add a remote endpoint: current Python SDK and policy gateways reject the native tag and query path. Session payload limits are not a global memory bound.
Move a parent, keep the relationship explicit
Native objects can now carry a generation-bearing parent link and an authored local transform. Reparenting can preserve either the object's world transform or its local transform. Moving a parent updates its descendants atomically.
The retained CPU example attaches child C to parent P, reparents C under Q without moving it in the world, rejects a cycle, moves Q and detaches C. Cycles, stale handles, ambiguous parent deletion and invalid numerical transforms reject the complete transaction. Parents require positive uniform world scale.
This native capability is separate from the Python room builder. Remote SDK and policy profiles reject hierarchy before scheduling. The CPU records establish neither physical-GPU behavior nor physics support.
A small room makes the control loop visible
A floor, back wall, side wall, table and stool are represented by five cubes. The scripted client assembles them through the existing east policy grant, then tries a batch containing a valid table move and a forbidden stool move. The rejection preserves the complete previous world. A corrected batch moves both objects within the permitted region.
This is an offline scripted provider using the public SDK, not a language model. The five live cubes consume 1,920 of the fixture's 2,048 retained charged bytes. Those numbers are deterministic policy accounting, not measured heap usage.
Permissions are checked before the world changes
The opt-in policy host has two separately credentialed principals with bounded write regions and explicit whole-world read grants. The coordinator checks complete cube bounds and commits world state and retained-memory sponsorship atomically.
Admission limits cover requests and working charges. The showcase uses the existing grant without expanding its permissions or quotas. After the sequence, idle observations check that outstanding request and working-byte usage return to zero.
A fixed-step owner feeds optional presentation
The earlier PR-006 slice adds a dedicated 60 Hz world owner and a separate scripted provider process. It caps catch-up at four executed ticks and reports discarded whole debt. Authoring revisions, simulation ticks and presentation stamps remain distinct.
The room showcase's optional Vulkan path renders detached snapshots and retains color, object-ID and depth attachments for revisions 3 and 4. Independent pixel checks compare expected object interiors and background while excluding a narrow expected-edge band.
Recovery is part of the interface
A lost or malformed mutation response can leave the result unknown even when the world changed. Legacy SDK profiles raise OutcomeUnknown and require explicit resynchronization. The separate opt-in retry profile retains a prepared request for explicit receipt recovery; neither path silently retries a change.
PR #12 integrated the Windows SDK compatibility correction after credential renewal. The original control host remains available alongside the newer agents and policy fixtures.
What was reviewed and what was actually run
The current source was checked on 30 September 2026 through PR #22. The worker table reads the retained PR-015-RESTART CPU archive. Earlier query evidence was reviewed on 21 September 2026 at 921c167980a0c2459c40e74d8d084e84437a0ce0. GitHub records native-query PR #16 as merged on 20 September, despite candidate wording in its evidence documents. Query pages belong to runtime 3b32f812232608af0203d579a9cb89ce9f71173c. Earlier hierarchy diagrams retain runtime 9630e3bf8dd934d7b91b6f06d0e458272d5d6e1c. This refresh reads their saved records without executing the engine.
The retained room evidence belongs to runtime de3d52e8a4937a1eae59c3a41b22f791fdd00149. It reports Windows CPU and physical-GPU proofs, regression proofs and hosted Windows/Linux checks. The gallery encodes original color readback bytes as lossless PNG and verifies decoded pixels against their recorded hashes. This portfolio refresh did not rerun the native engine.
What is still experimental
Linux physical-GPU verification remains not_run. Physics, richer mesh, voxel and pixel editing, and performance targets remain future slices. Bounded native persistence is implemented separately. This tiny fixture is not a finished editor or game.
Native read grants and query filtering do not extend the fixed two-principal remote policy fixture. General fairness, remote queries and arbitrary agent safety remain unestablished. No released Python installation package, language-model execution or production-readiness claim is made.
Related writing
Related updates
Inspect the checked source
Evidence reviewed . Individual decisions and captured examples retain their own source revisions and limitations.
Read the checked README (opens in a new tab)- Worker lifecycle merge (opens in a new tab) ↗
- Restart-expiry correction merge (opens in a new tab) ↗
- Worker lifecycle contract (opens in a new tab) ↗
- Retained restart-expiry evidence (opens in a new tab) ↗
- Concurrent proposals and retained retries (opens in a new tab) ↗
- Native undo and redo (opens in a new tab) ↗
- Recorded command replay (opens in a new tab) ↗
- Separate native persistence contract (opens in a new tab) ↗
- Native query merge (opens in a new tab) ↗
- Query CPU evidence (opens in a new tab) ↗
- Native hierarchy merge (opens in a new tab) ↗
- Hierarchy CPU evidence (opens in a new tab) ↗
- Room showcase merge (opens in a new tab) ↗
- Room capture evidence (opens in a new tab) ↗
- Runnable room example (opens in a new tab) ↗
- Policy and budget handoff (opens in a new tab) ↗
- SDK compatibility correction (opens in a new tab) ↗
- Fixed-step provider handoff (opens in a new tab) ↗